U.S. Department of the Interior 
PRIVACY IMPACT ASSESSMENT 





Introduction 


The Department of the Interior requires PIAs to be conducted and maintained on all IT systems whether 
already in existence, in development or undergoing modification in order to adequately evaluate privacy 
risks, ensure the protection of privacy information, and consider privacy implications throughout the 
information system development life cycle. This PIA form may not be modified and must be completed 
electronically; hand-written submissions will not be accepted. See the DOI PIA Guide for additional 
guidance on conducting a PIA or meeting the requirements of the E-Government Act of 2002. See 
Section 6.0 of the DOI PIA Guide for specific guidance on answering the questions in this form. 


NOTE: See Section 7.0 of the DOI PIA Guide for guidance on using the DOI Adapted PIA template to 
assess third-party websites or applications. 


Name of Project: BisonConnect — GAfG-Google Apps for Government Decommissioning 
Bureau/Office: Office of the Chief Information Officer 

Date: May 6, 2021 

Point of Contact 

Name: Teri Barnett 

Title: Departmental Privacy Officer 

Email: DOL Privacy@ios.doi.gov 

Phone: 202-208-1605 

Address: 1849 C Street, NW Room 7112, Washington DC 20240 


Section 1. General System Information 


A. Isa full PIA required? 
O Yes, information is collected from or maintained on 
L Members of the general public 
Ll Federal personnel and/or Federal contractors 
CL] Volunteers 
O All 


No: Information is NOT collected, maintained, or used that is identifiable to the individual in 
this system. Only sections I and 5 of this form are required to be completed. 


B. What is the purpose of the system? 
Google Apps for Government (BisonConnect — GAfG ) has been decommissioned. 


BisonConnect — GAfG was a cloud-based “Software as a Service” (SaaS) offered by Google that 
contained a suite of Google applications and tools including email, calendar, instant messaging, 


BisonConnect — GAfG-Google Apps for Government Decommissioning 
Privacy Impact Assessment 





document development, collaboration and production and cloud storage applications, and was 
accessible through web browsers with secured (https) connections and from most internet- 
connected devices by using mobile devices. BisonConnect — GAfG contained multiple 
applications: Mail, Calendar, Contacts, Drive, Sites, Browser and Chat. BisonConnect — GAfG 
was the DOI e-mail system used enterprise-wide. Bison Connect GAfG was hosted and 
managed by Google, with only simple administrative functions related to user and group 
management being performed by DOI, that were accessible to DOI via a web-based console 
access product entitled cPanel, or by using a synchronization tool entitled Google Active 
Directory Sync (GADS). DOI data remained in the US. Google owned and managed the bulk of 
the controls and DOI had the means to evaluate control descriptions, documentation, test results, 
and vulnerabilities identified. DOI had configured Google Docs and Sites to prohibit sharing 
information outside of the DOI domain. All DOI email was processed, copied, and stored in the 
eMail Enterprise Records and Document Management System (CERDMS) system. 


All bureau/office data in the BisonConnect GAfG which includes Google Mail, Google Drive 
and Google Sites was migrated to the new DOI Microsoft Office 365 (0365) cloud environment. 
Google Forms and custom applications were redeveloped in the new 0365 cloud environment. 


The BisonConnect GAfG contract ended March 22, 2020. The Department of the Interior (DOT) 
managed the migration of all data which was verified OS/OCIO system owner. The DOI 
Contracting Officer gave the approval to delete the cloud environment and associated data, and 
Google confirmed via email on August 28, 2020 that all data was deleted. 


DOI developed a decommissioning plan to ensure privacy, security and records requirements 
were met. Data was securely migrated to the new 0365 environment. BisonConnect GAfG was 
a cloud system, therefore DOI has no hardware or equipment that require sanitization or disposal. 
DOI conducted a PIA to evaluate the privacy risks for use of the 0365, which is posted in 
CSAM and available on the DOI PIA website. 


. What is the legal authority? 


Departmental Regulations, 5 U.S.C. 301; The Paperwork Reduction Act, 44 U.S.C. Chapter 35; 
the Clinger-Cohen Act, 40 U.S.C. 1401; OMB Circular A-130, Management of Federal 
Information Resources; Executive Order 13571, “Streamlining Service Delivery and Improving 
Customer Service,” April 11, 2011; Presidential Memorandum, “Security Authorization of 
Information Systems in Cloud Computing Environments,” December 8, 2011; and Presidential 
Memorandum, “Building a 21st Century Digital Government,” May 23, 2012. 


. Why is this PIA being completed or modified? 


O New Information System 
O New Electronic Collection 
O Existing Information System under Periodic Review 
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L Merging of Systems 

O Significantly Modified Information System 

L Conversion from Paper to Electronic Records 

Retiring or Decommissioning a System - BisonConnect — GAfG has been decommissioned 
O Other: Describe 


. Is this information system registered in CSAM? 


Yes: Enter the UII Code and the System Security Plan (SSP) Name 


010-000002539; BisonConnect — GAfG - Google Apps for Government System Security and 
Privacy Plan approved March 24, 2020. 


O No 


. List all minor applications or subsystems that are hosted on this system and covered under 
this privacy impact assessment. 








Subsystem Name Purpose Contains PII Describe 
(Yes/No) If Yes, provide a 
description. 
N/A N/A N/A N/A 




















. Does this information system or electronic collection require a published Privacy Act 
System of Records Notice (SORN)? 


O Yes: List Privacy Act SORN Identifier(s) 
No 


. Does this information system or electronic collection require an OMB Control Number? 


O Yes: Describe 
No 


